"Are You Sure?": An Empirical Study of Human Perception Vulnerability in LLM-Driven Agentic Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Xinfeng, Dai, Shenyu, Zheng, Kelong, Xiao, Yue, Deng, Gelei, Dong, Wei, Wang, Xiaofeng
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915814507020288
author Li, Xinfeng
Dai, Shenyu
Zheng, Kelong
Xiao, Yue
Deng, Gelei
Dong, Wei
Wang, Xiaofeng
author_facet Li, Xinfeng
Dai, Shenyu
Zheng, Kelong
Xiao, Yue
Deng, Gelei
Dong, Wei
Wang, Xiaofeng
contents Large language model (LLM) agents are rapidly becoming trusted copilots in high-stakes domains like software development and healthcare. However, this deepening trust introduces a novel attack surface: Agent-Mediated Deception (AMD), where compromised agents are weaponized against their human users. While extensive research focuses on agent-centric threats, human susceptibility to deception by a compromised agent remains unexplored. We present the first large-scale empirical study with 303 participants to measure human susceptibility to AMD. This is based on HAT-Lab (Human-Agent Trust Laboratory), a high-fidelity research platform we develop, featuring nine carefully crafted scenarios spanning everyday and professional domains (e.g., healthcare, software development, human resources). Our 10 key findings reveal significant vulnerabilities and provide future defense perspectives. Specifically, only 8.6% of participants perceive AMD attacks, while domain experts show increased susceptibility in certain scenarios. We identify six cognitive failure modes in users and find that their risk awareness often fails to translate to protective behavior. The defense analysis reveals that effective warnings should interrupt workflows with low verification costs. With experiential learning based on HAT-Lab, over 90% of users who perceive risks report increased caution against AMD. This work provides empirical evidence and a platform for human-centric agent security research.
format Preprint
id arxiv_https___arxiv_org_abs_2602_21127
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle "Are You Sure?": An Empirical Study of Human Perception Vulnerability in LLM-Driven Agentic Systems
Li, Xinfeng
Dai, Shenyu
Zheng, Kelong
Xiao, Yue
Deng, Gelei
Dong, Wei
Wang, Xiaofeng
Human-Computer Interaction
Artificial Intelligence
Cryptography and Security
Social and Information Networks
Large language model (LLM) agents are rapidly becoming trusted copilots in high-stakes domains like software development and healthcare. However, this deepening trust introduces a novel attack surface: Agent-Mediated Deception (AMD), where compromised agents are weaponized against their human users. While extensive research focuses on agent-centric threats, human susceptibility to deception by a compromised agent remains unexplored. We present the first large-scale empirical study with 303 participants to measure human susceptibility to AMD. This is based on HAT-Lab (Human-Agent Trust Laboratory), a high-fidelity research platform we develop, featuring nine carefully crafted scenarios spanning everyday and professional domains (e.g., healthcare, software development, human resources). Our 10 key findings reveal significant vulnerabilities and provide future defense perspectives. Specifically, only 8.6% of participants perceive AMD attacks, while domain experts show increased susceptibility in certain scenarios. We identify six cognitive failure modes in users and find that their risk awareness often fails to translate to protective behavior. The defense analysis reveals that effective warnings should interrupt workflows with low verification costs. With experiential learning based on HAT-Lab, over 90% of users who perceive risks report increased caution against AMD. This work provides empirical evidence and a platform for human-centric agent security research.
title "Are You Sure?": An Empirical Study of Human Perception Vulnerability in LLM-Driven Agentic Systems
topic Human-Computer Interaction
Artificial Intelligence
Cryptography and Security
Social and Information Networks
url https://arxiv.org/abs/2602.21127